Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: IIS session & application variables |
|---|---|
| Date: | Fri, 26 Nov 2004 07:30:36 +0200 |
Hi Martin
Session variables are not "sent from page to page", but rather stored in memory
using the Session ID. The app (or page) has access to these variables using the
Session ID (Behind the scenes).
If you want to see the information flowing to / from browser then goto
www.planet-source-code.com and search there for "html breakout box". This
little VB6 App will allow you to see the HTML traffic to / from the browser
(via the proxy program). If you don't come right I will look for it and send
you the link.
However you can see the session variables on a ASP page using the following
code (classic ASP) It is made for my environment, but I am sure you will be
able to figure it out:
Sub SFDebug()
REM ------------------------------------------------------------
REM -- Allows a person to see Session and Form Debug Information
rem -- if CANDebug is Enabled
REM ------------------------------------------------------------
Dim strSessionContents 'as String
Dim strFormContents 'as String
Dim strURLContents 'as String
Dim objFIELD 'as
String
Dim formElement 'as
Dim URLElement 'as
If Session("UserDebug") = true and CANDebug=TRUE then
strSessionContents = ""
strFormContents = ""
strURLContents = ""
REM -- Create a list of all Session Varables
On Error Resume Next
For Each objFIELD in Session.Contents
strSessionContents = strSessionContents & _
Left(objFIELD & " ",20) & ":
[" & Session(objFIELD) & "]" & vbcrlf
Next 'objFIELD
On Error Goto 0
REM -- Bread Crumm Add On
Dim DKeys
Dim DItems
Dim I
Dim DictTmp
If IsObject(Session("Dictionary")) then
Set DictTmp = Session("Dictionary")
DKeys = DictTmp.Keys
DItems = DictTmp.Items
For i = 0 To DictTmp.Count -1
strSessionContents =
strSessionContents & _
Left("Dict(" & DKeys(I) & ")
",30) & ": [" & DItems(I) & "]" & vbcrlf
'Response.Write "Dict." &
DItems(I) & " = [" & DKeys(I) & "]<br>"
Next 'I
Set DictTmp = Nothing
end if
REM -- Bread Crumm Add On TILL HERE
REM -- Create a list of all Used Form Elements
strFormContents = ""
For Each formElement In Request.Form
strFormContents = strFormContents & _
Left(formElement & " ",20) & ": [" &
Request.form(formElement) & "]" & vbcrlf
Next 'formElement
REM -- Create a list of all Used URL Elements
(QueryString)
strURLContents = ""
For Each URLElement In Request.QueryString
strURLContents = strURLContents & _
Left(URLElement & " ",20) & ": [" &
Request.QueryString(URLElement) & "]" & vbcrlf
Next
Response.Write "<div style=""BACKGROUND-COLOR: #ffffbb;
font-size:10px"">" & _
"<pre>" & _
"Session Variables" & vbcrlf & _
"-----------------" & vbcrlf & _
strSessionContents & vbcrlf & _
"Form Variables" & vbcrlf & _
"---------" & vbcrlf & _
strFormContents & vbcrlf & _
"URL Variables" & vbcrlf & _
"-----------------" & vbcrlf & _
strURLContents & vbcrlf & _
"</pre>" & _
"</div>"
end if
end Sub
-----Original Message-----
From: Bénoni MARTIN [mailto:Benoni.MARTIN@libertis.ga]
Sent: 25 November 2004 10:22
To: webappsec@securityfocus.com
Subject: IIS session & application variables
Hi list !
I was wondering if someone knows about a tool that can get the
application/session variables on my IIS session ...
Lets' me explain: I've got an IIS server, and some application & session
variables defined in my global.asa. I think these variables are sent from one
page to another one, and I was wondering if there is a tool that displays me
these variables (session and application variables).
Any clue would be helpful !
Thanks in advance !
Confidentiality Warning
=======================
The contents of this e-mail and any accompanying documentation
are confidential and any use thereof, in what ever form, by anyone
other than the addressee is strictly prohibited.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Article - A solution to phishing, Peter Conrad |
|---|---|
| Next by Date: | Re: Article - A solution to phishing, John West |
| Previous by Thread: | Re: IIS session & application variables, saphyr |
| Next by Thread: | RE: [BAD-DATE] Threat Modeling, Arian J. Evans |
| Indexes: | [Date] [Thread] [Top] [All Lists] |